CVE-2026-86247 PUBLISHED

Apache Tomcat Native: Client certificate requirements can be down-graded

Assigner: apache
Reserved: 06.09.2026 Published: 23.09.2026 Updated: 23.09.2026

Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations.

This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected.

Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Tomcat Native
Versions Default: unaffected
  • affected from 2.0.0 to 2.0.15 (incl.)
  • affected from 1.3.0 to 1.3.8 (incl.)

References

Problem Types

  • CWE-366 Race condition within a thread CWE